Two users have been receiving more than 100 phishing, newsletter, and other spam messages per day for about three weeks. The messages come from constantly changing domains, IP addresses, and languages, so blocking individual senders has not helped. I'm considering applying an aggressive, user-specific policy in our email security system, but I'd like to know what has worked for others over the long term. The attackers have also been calling through Teams while pretending to be IT support and offering to fix the email problem.
4 Answers
Treat the mail flood as possible cover for another attack, not just an annoying spam problem. Search the affected mailboxes across the entire period for purchase confirmations, password resets, account changes, invoices, wire instructions, and other legitimate notifications that may be buried. Review sign-in activity, mailbox rules, payment changes, and any unusual account access, then reset passwords and verify MFA if there is any suspicion of compromise. Also warn the users not to let anyone claiming to be IT take remote access or troubleshoot through an unsolicited call.
As a temporary workaround, changing the users’ primary email addresses can sometimes stop the flood, but it is disruptive and may not work if the attacker continues targeting the old addresses. Another option is to keep accepting mail into a separate mailbox and filter or review it there while the main addresses are protected. If your provider supports it, a tarpitting or throttling service can also keep the volume from overwhelming the users without relying on sender blocks.
A dedicated email-security policy can reduce the visible flood. Features such as registration-bomb or email-bomb detection, language or geographic filtering, and rules targeting common unsubscribe or bulk-mail patterns can help, especially when applied only to the affected users. Keep in mind that blocking domains and IPs alone usually fails because the messages come from legitimate services and constantly changing senders. Put the messages into quarantine or a holding mailbox rather than deleting everything, so legitimate mail can still be recovered.
Restrict external communication in Teams while this is happening. Disable external access where possible, or use an allowlist for trusted organizations, and make sure users know that real IT staff will not unexpectedly ask for credentials or remote access. The follow-up call is often the more dangerous part of the campaign.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures